| (I) An organization "that coordinates and supports the response to
security incidents that involve sites within a defined
constituency." [R2350] (See: CERT, FIRST, security incident.)
(C) To be considered a CSIRT, an organization must do as follows:
- Provide a (secure) channel for receiving reports about
suspected security incidents.
- Provide assistance to members of its constituency in handling
the incidents.
- Disseminate incident-related information to its constituency
and other involved parties.
|